3 ms·
The archive.org links were used at the creation of the blog post. (which was not necessarily the release date ;-) - needed to find some time to write it) So Wo
by LukasReschke 11y ago
The archive.org links were used at the creation of the blog post. (which was not necessarily the release date ;-) - needed to find some time to write it)
So Wordpress is an interesting example. Because the CVE assignment date has nothing to do with the release date of the patches. Wordpress doesn't request the CVE on their own.
So we're still at a 4-5 day delay (https://wordpress.org/news/2016/02/wordpress-4-4-2-security-and-maintenance-release/ https://wordpress.org/news/2016/02/wordpress-4-4-2-security-...) for security fixes for a web-facing software. This is still far worse than just enabling automatic updates in Wordpress. I have not much problems if that would be a locally exploitable vuln, but web software usually is exploitable via web.
When it comes to web software I believe it's unacceptable to add any additional delay. (sure those bugs were not that severe, but as other examples in the blog show the problem with delayed or never updated packages is inherent)
- danieldk 11y agoThe archive.org links were used at the creation of the blog post. I still find it disingenuous to use an archive.org link dated February 7 on February 13. So we're still at a 4-5 day delay for security fixes for a web-facing software. I agree that this is (far) too long. I just dislike the sensational tone of your blog post and subtle bending of facts. Linking to the Wordpress 4.4.2 release page and the Debian changelog would have been factual and convincing. Pointing to a week-old webpage, which was outdated on even the original date is just sloppy or manipulative.
- LeonidasXIV 11y ago> This is still far worse than just enabling automatic updates in Wordpress. A webapp updating itself, having write access to its files (I see zero privilege separation in [1]) and getting updates from a hopefully not compromised source (see Linux Mint lately), that's just asking for trouble. I trust the Debian mirror infrastructure with signed packages that are updated by a privileged system user way more. [1]: https://codex.wordpress.org/Configuring_Automatic_Background_Updates https://codex.wordpress.org/Configuring_Automatic_Background...